io.github.pixelvault-dev/pixelvault

MCPcommunitylive
v0.3.0io.github.pixelvault-devUnknownUpdated 2mo ago

Agent-first image hosting — upload images and get instant CDN URLs.

Endpoint healthlive
checked 7 days ago · 202ms · 2 endpoints · auth required
100% of the last 5 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
2mo agoLast update
Package
Authorio.github.pixelvault-dev
LicenseUnknown
Version0.3.0
Sourcemcp-registry
Trust Status
D
30/100Risk
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
—Prompt-injection scan · findings+0/30
→ Publisher: remove instructions in the source aimed at AI clients rather than human readers
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface8 tools · 3 privileged
Security scan⚠ Warnings (1)vlive · 25d agoHow well does this scan work?
PROMPTtool:get_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:list_imagesLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:upload_batchLinks to undeclared domain: pixelvault.dev
PROMPTtool:transform_imageLinks to undeclared domain: pixelvault.dev
PROMPTtool:rescue_imgurExfiltration-shaped instruction
EvalsNone
IndexedJun 20, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

8 tools · 3 privileged · 1 flagged for injection
Observed live from the vendor's endpoint25d ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://mcp.pixelvault.dev/mcp8 tools · 259ms
  • https://mcp.pixelvault.dev/mcp/oauthauth required
get_imageGet metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

Get metadata (CDN URL, size, MIME type, dimensions) for one PixelVault image by id. Maps to GET /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop…

NOTELinks to undeclared domain: pixelvault.dev
ParameterTypeDescription
id*stringImage id to fetch, e.g. img_abc123
list_imagesList images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

List images in your PixelVault project, most recent first. Maps to GET /v1/images with pagination. Requires a PixelVault API key sent as a Bearer token in the Authorization header. The returned CDN URL supports on-the-fly transforms via query params — e.g. ?w=400&fit=cover (resize/crop), ?fmt=webp…

NOTELinks to undeclared domain: pixelvault.dev
ParameterTypeDescription
pageintegerPage number (default 1)
per_pageintegerItems per page (default 20, max 100)
delete_imageprivilegedPermanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

Permanently delete one PixelVault image by id. Maps to DELETE /v1/images/:id. Requires a PixelVault API key sent as a Bearer token in the Authorization header.

ParameterTypeDescription
id*stringImage id to delete, e.g. img_abc123
upload_imageprivilegedUpload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

Upload an image to PixelVault and get an instant CDN URL. Maps to POST /v1/images. Provide exactly one of `source_url` (a public http(s) URL the server fetches) or `data` (base64-encoded bytes); optional `folder`, `filename`, and `expires_in` (seconds, for an auto-expiring image). Max 5 MB; JPG/PNG…

NOTELinks to undeclared domain: pixelvault.dev
ParameterTypeDescription
source_urlstringPublic http(s) URL of an image to fetch and upload. Provide this OR data.
datastringBase64-encoded image bytes (data URLs accepted). Provide this OR source_url.
folderstringOptional folder/path prefix for the image.
filenamestringOptional original filename, e.g. photo.png.
expires_inintegerOptional time-to-live in seconds. The image is auto-deleted after this many seconds (must be 60–2,592,000, i.e. 1 minute to 30 days). Omit for a permanent imag…
upload_batchprivilegedUpload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

Upload many images (1–50) in one call, grouped into a collection — e.g. a CI run or a set of generated variants. Maps to POST /v1/images/batch. Each item is `data` (base64) or `source_url` (server-fetched, SSRF-guarded), with optional `filename`/`metadata`. Set `visibility: "private"` to get a sign…

NOTELinks to undeclared domain: pixelvault.dev
ParameterTypeDescription
images*array1–50 images to upload into the collection.
typestringCollection type/discriminator (e.g. ci_build, generation). Default 'batch'.
namestringIdempotency key — re-running with the same (type, name) upserts the same collection.
visibilitystring'private' returns a signed URL per image (free plan: up to 100 private images); 'public' returns a plain CDN URL. Default 'public'.
expires_inintegerImage deletion TTL in seconds (60–2,592,000). Omit for permanent.
sign_expires_inintegerSignature lifetime for private URLs in seconds (60–2,592,000, default 7 days).
metadataobjectFreeform collection metadata, e.g. { commit, pr_number, branch }.
sign_urlMint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

Mint a time-limited signed URL for a private image. Maps to POST /v1/images/:id/sign-url. Provide `id` and optional `expires_in` (seconds, default 3600). The signature binds the image, so the URL can't be replayed against another image; strip it and the CDN returns 403. Deleting the image revokes i…

ParameterTypeDescription
id*stringImage id to mint a signed URL for, e.g. img_abc123.
expires_inintegerSignature lifetime in seconds (60–2,592,000). Default 3600 (1 hour).
transform_imageBuild an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

Build an on-the-fly transform URL for a PixelVault image (resize, crop, format/quality, AI background removal, blur/sharpen/rotate/flip, brightness/contrast/saturation, and same-project watermark tiling). Provide exactly one of `url` (a PixelVault CDN URL) or `id` (an image id, resolved via the API…

NOTELinks to undeclared domain: pixelvault.dev
ParameterTypeDescription
urlstringAbsolute CDN URL of a PixelVault image, as returned by upload_image / get_image / list_images. Provide this OR id.
idstringPixelVault image id (e.g. img_abc123); its CDN URL is resolved via the API. Provide this OR url. Requires an API key when used.
sizestringNamed size preset: s=256px, m=640px, l=1280px, social=1200x630 OG card. Wins over width/height.
widthintegerTarget width in px (1..4000). Snapped UP to the nearest allowed step. scale-down never upscales.
heightintegerTarget height in px (1..4000). Snapped UP to the nearest allowed step.
fitstringResize mode. scale-down (default) never enlarges; contain/cover/crop/pad resize to the exact box and may upscale. Only meaningful alongside width/height.
formatstringOutput format. auto negotiates WebP/AVIF from the client's Accept header.
qualitystringOutput quality. auto lets Cloudflare choose.
segmentstringAI background removal (BiRefNet): foreground keeps the subject and makes the background transparent. Output is forced to PNG unless an opaque background is set…
backgroundstringFill color behind a removed (segment) or padded (fit=pad) background: hex (#ffaa00), rgb()/rgba(), or a common CSS color name. No effect otherwise.
gravitystringCrop anchor, only with fit=cover|crop: face, left, right, top, bottom, auto, or 'XxY' coords 0.0-1.0. face enables zoom.
zoomnumberFace-crop tightness 0.0-1.0, only with gravity=face.
blurnumberGaussian blur (0-250); snapped to the nearest of 10/30/60/120. <=0 is ignored.
sharpennumberSharpen strength (0-10); snapped to the nearest of 1/3/5.
rotatenumberRotate clockwise; rounded to the nearest right angle (90/180/270).
flipstringMirror horizontally (h), vertically (v), or both (hv).
brightnessnumberBrightness multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
contrastnumberContrast multiplier 0-2 (1=no change); snapped to 0.5/0.75/1.25/1.5/2.
saturationnumberSaturation multiplier 0-2 (1=no change, 0=grayscale); snapped to 0/0.5/1.5/2.
tilestringFilename (optionally folder-prefixed, with extension) of another image in the SAME project to tile edge-to-edge as a watermark, e.g. watermark.png.
rescue_imgurinjection riskScan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

Scan a web page for hotlinked Imgur images and return a PixelVault rescue URL for each — a proxy that lazily rehosts the image on first request, keeping it working through the UK Imgur block. The anonymous rescue tier is a durable ~30-day edge cache (see `cache_ttl_days` in the result), not permane…

INJECTIONExfiltration-shaped instructionot permanent storage. Maps to POST /v1/imgur-scan (server-side page fetch; no API key required). Provide `page_url`…
ParameterTypeDescription
page_url*stringPublic https:// URL of a page to scan for hotlinked Imgur images.

8 of 8 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Agent-first image hosting — upload images and get instant CDN URLs.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.